GitHub Advanced Security Integration with DefectDojo
GitHub Advanced Security is a comprehensive developer-first application security platform that integrates static application security testing (SAST) with CodeQL, secret scanning with push protection, software composition analysis (SCA) with Dependabot, dependency review, and AI-powered Copilot Autofix to identify and remediate vulnerabilities, exposed credentials, and insecure dependencies throughout the software development lifecycle. The platform operates natively within GitHub workflows to provide automated security scanning, compliance monitoring, security campaigns for backlog remediation, and centralized security insights across repositories, enabling development teams to build secure code by default while freeing security teams to focus on strategic initiatives.
Data Granularity: What Gets Imported
The following fields are captured from GitHub Advanced Security results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "GitHub Advanced Security",
"engagement": "<engagement-id>",
"file": "results.json"
}